All Apps and Add-ons

No Data in Splunk App for Active Directory

jhutto
Explorer

I recently setup a trial Splunk server in my environment, and one of the compents I would like to try is the Splunk App for Active Directory. I also installed the prerequisite apps: Sideview Utils and Windows Technology Add-on.
For data inputs, I have Splunk monitoring the remote event logs on my domain controllers as well as a base DN in Active Directory. I've let it run for almost 24 hours, but there is no data displayed in the Splunk App for Active Directory. Using the built-in Search App, I can find account lockout events, failed logins, etc., but nothing is being displayed in the AD App.
I'm pretty new to Splunk, so I'm sure it's something obvious I've overlooked.

Thanks in advance for any help you can provide.

1 Solution

ahall_splunk
Splunk Employee
Splunk Employee

The Splunk App for Active Directory requires that additional technology add-ons be placed on a Universal Forwarder on your Domain Controllers. The app requires that inventory information is retrieved from each domain controller, so it doesn't work with remote collection.

See the documentation on this app at http://docs.splunk.com

View solution in original post

ahall_splunk
Splunk Employee
Splunk Employee

The Splunk App for Active Directory requires that additional technology add-ons be placed on a Universal Forwarder on your Domain Controllers. The app requires that inventory information is retrieved from each domain controller, so it doesn't work with remote collection.

See the documentation on this app at http://docs.splunk.com

jhutto
Explorer

Thank you!

0 Karma

ahall_splunk
Splunk Employee
Splunk Employee

No. You need to install the Universal Forwarder on your Domain Controllers, configuring it to send events to your central splunk instance, and then install the Splunk_TA_windows and the appropriate Technology Add-ons in appserver/addons of the Splunk for Active Directory app.

Remote data collection is NOT supported with the Splunk for Active Directory app.

0 Karma

jhutto
Explorer

So I need to install that remote collection agent on my DCs?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...